Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

621–630 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#621
post #223

is it worth to buy google pixel just for installing grapheneos? in my country, it is kinda pricey and of course it cannot install bank apps because almost all of them are must non root phone.

Break free from Google by buying their hardware and be dependant on them to actively support the device. Things are absurd at this stage. I guess there is different motivations behind mobile OSes.

"Break free from Google," is not GrapheneOS's motivation, just so people are aware. That is the blog writer's motivation.

Re: GrapheneOS – Break Free from Google and Apple

#622

GrapheneOS needs at least the modem blob provided by the OEM. It runs as root, it has full network control. Same could go for other "drivers" like wifi+bluetooth. Privacy is more a dream than a real thing.

They are working on getting their own hardware.

Re: GrapheneOS – Break Free from Google and Apple

#623

It's very annoying that they restrict themselves to Pixels. I get they can't guarantee all the security features they want on other phones, but even a subset of those security features and the other advantages like the lack of cruft would make it very attractive to be able to run on other phones.

I can understand the frustration, but it wouldn't be right to say they 'restrict themselves to Pixels'. They believe strongly in a standard for privacy/security of people's personal devices, and unfortunately only Pixels are close to meeting those standards. It's not even like Pixels are their ideal device.

I feel the frustration should be targeted at OEMs that don't meet very reasonable requirements like minimum 5 years of monthly (timely) security updates.

Re: GrapheneOS – Break Free from Google and Apple

#624
post #604

Earlier quoted context omitted.

Needing to use a verified boot chain with keys that the bank trusts is essentially the same as using the authenticator device from said bank, It's not, because even though the authenticator is secure, you are entering the auth codes in a browser in general purpose desktop OS with (if you use Windows or desktop Linux) little to no sandboxing outside the browser. You are one malware app (or NodeJS package for tech user…

That seems wrong. If malware can fake what the authenticator shows me, the authenticator is broken! It doesn't matter what device relays the code I typed over or otherwise transmits the approval through untrusted networks to the server > The sad reality is that phones (and some tablets) are the only relatively secure computing environments that we have My bank('s authenticator hardware) begs to differ

That seems wrong. If malware can fake what the authenticator shows me, the authenticator is broken!

That's not what I am saying. The authenticator is irrelavant to this attack. If your machine is compromised by malware, the malware could take over the browser session, regardless of how you log in.

Phones are better protected against persistent malware because every application is sandboxed (harder to escalate) and much more of the boot chain/OS is validated (harder to persist).

Re: GrapheneOS – Break Free from Google and Apple

#625
post #26

Earlier quoted context omitted.

It should probably be "break free from Google and Apple"?

how will it help you to break free from apple if it only supports pixel phones?

They are working on making their own phone hardware.

Re: GrapheneOS – Break Free from Google and Apple

#626

Earlier quoted context omitted.

Meanwhile, it's probably A-OK for the app to run on a phone that hasn't received security updates for 5 years. I don't get it. If they're worried about liability, why not check the security patch level and refuse to run on phones that aren't up to date? I'm guessing it's because there are a lot of phones floating around that aren't updated (probably far more than are rooted), and they're willing to pretend to be secu…

> If they're worried about liability, why not check the security patch level and refuse to run on phones that aren't up to date? Google doesn't provide an API or data set to figure out what the current security patch level is for any particular device. Officially, OEMs can now be 4 months out-of-date, and user updates lag behind that. Your guess is good, but misses the point. Banks are worried about a couple things w…

All good points. Thanks for that!

I'm not an Android developer, but I was thinking they could use something like the android.os.Build.VERSION.SECURITY_PATCH call to get the security patch level. Maybe that's not sufficient for that purpose, though.

Re: GrapheneOS – Break Free from Google and Apple

#629
"Break free from Google ..." by purchasing Google hardware and using [software "based on"] Google software

Is it really "breaking free" from a company if the method of "breaking free" requires continued cooperation from the company

This is not to suggest using a modified version of Android isn't useful. This comment is not about GrapheneOS. (But there will be HN replies that will try to redirect focus to it anyway.) This comment is about claiming it's possible to "break free" from something while still remaining inextricably tied to it

In addition to using a custom ROM, there are methods of stopping the Pixel's attempts to "phone home" to the company that work even with the version of Android pre-installed by the company intact. However if a method requires software, e.g., drivers, or is "based on" software controlled by the company, then ultimately the company holds the cards. IMHO, this is not what it means to "break free"

Perhaps the most reliable method of stopping these connections to the company is one that does not rely on cooperation by the company. This is because if the company decides to stop cooperating, the method still works

Re: GrapheneOS – Break Free from Google and Apple

#630

One of the only big downsides I've noticed with GrapheneOS is that several banking apps don't work with it at all thanks to being tied to Google's verification ecosystem. Luckily I have hardware 2FA keys from my bank so I can authenticate using that. It also slightly decreases the suck-factor from whenever the phone decides to fly off down a drain. This may not be the case for you, so do your research on what you nee…

I contacted my bank, insisting that GrapheneOS is one of the most secure OS on the market and therefore should be supported if they actually care about users' security (it's actually far more secure than all the old, far less secure but Google-approved devices out there). They acknowledged an fixed their app, one of the most popular in France. Still missing Android Pay but that's due to Android Pay being closed. I wi…

Play Integrity and APIs like it aren't about security, they are about anti-fraud/anti-scam.
Post reply on HN